Impact
The vulnerability is an Insecure Direct Object Reference flaw in the Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin. During the post‑duplication AJAX operation the plugin neglects to perform a per‑object capability check, enabling any user with Contributor‑level access or higher to duplicate any post—regardless of the original owner, post type, or status—into a new published post that they own. The duplicated copy contains the same private metadata as the original, including secrets that were intended to be protected. The result is a loss of confidentiality, as hidden data becomes readable by users who should not have access to it.
Affected Systems
WordPress sites deployed with Kali Forms version 2.4.17 or earlier are impacted. Any user assigned the Contributor role or higher on those sites can exploit the flaw. The issue relates specifically to the Kali Forms — Contact Form & Drag-and-Drop Builder plugin and does not apply to other plugins or core WordPress components.
Risk and Exploitability
With a CVSS score of 5.5 the vulnerability is rated moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack can be carried out entirely within a WordPress installation without external network access, requiring only user credentials that grant Contributor privileges. The principal risk is the disclosure of private post metadata that may include sensitive or secret values stored by the plugin.
OpenCVE Enrichment